arXiv AI

Security and Detectability Analysis of Unicode Text Watermarking Methods against Large Language Models

arXiv:2512. 13325v2 Announce Type: replace-cross Abstract: Securing digital text is becoming increasingly relevant due to the widespread use of large language models.

arXiv Computation and Language
Sep 7

Robust Text Watermarking for Large Language Models via Dual Semantic Embeddings

The paper introduces Dual-Embedding Watermarking (DEW), a semantic watermarking technique for large language models that combines contextual and token-level embeddings. DEW applies algebraic vector-space operations to generate a watermark signal that remains robust to paraphrasing and translation, while obfuscating the signal with pseudo-random matrices seeded by a secret key. Experiments demonstrate state‑of‑the‑art robustness, especially against translation, with minimal computational overhead and preserved text quality at lower watermark strengths.

By Jonas Sch\"afer, Cezary Pilaszewicz, Gerhard Wunder
arXiv AI
Sep 1

Disappearing Ink: Obfuscation Breaks N-gram Code Watermarks in Theory and Practice

The paper demonstrates that N‑gram based code watermarking schemes, widely used to identify machine‑generated code, are ineffective when faced with realistic code obfuscation. By modeling semantics‑preserving transformations as a Markov random walk and introducing the assumption of distribution consistency, the authors prove that obfuscation can drive the failure rate of any detector to nearly 1 minus its false‑positive rate. Extensive experiments across multiple watermarking methods, LLMs, languages, benchmarks, and obfuscators confirm that detectors collapse to near‑random performance (AUROC ≈ 0.5) after obfuscation.

By Gehao Zhang, Mingzhe Li, Eugene Bagdasarian, Shiqing Ma, Juan Zhai
arXiv Machine Learning
Jul 2

Watermarking for Proprietary Dataset Protection

arXiv:2607. 00325v1 Announce Type: new Abstract: A growing body of literature suggests that training data membership inference problems are fundamentally hard tasks in modern language modeling settings.

By John Kirchenbauer, Brian R. Bartoldson, Bhavya Kailkhura, Tom Goldstein
arXiv Computation and Language
4d ago

TTMark: Pairwise Distortion-Free Watermarking Beyond Single-Token Entropy

TTMark introduces a pairwise watermarking framework that extends distortion‑free watermarking from single tokens to adjacent token pairs, enlarging the watermarking alphabet from V to V². By watermarking the joint distribution of consecutive tokens, the detector can exploit both token entropy and conditional entropy while maintaining distortion‑freeness. Experiments on multiple language models and datasets show that TTMARK improves detectability, robustness to edits, and localized watermark detection without degrading generation quality.

By Ruibo Chen, Zhengmian Hu, Donghang Lu, Xuehao Cui, Georgios Milis, Yihan Wu, Jian Du, Heng Huang